Vulnerability record · CVE-2011-3494 · published 16 September 2011
CVE-2011-3494: eSignal WinSig.exe buffer overflow via crafted QUO, SUM, POR or font files
Interactivedata · Esignal
WinSig.exe in eSignal 10.6.2425 and earlier contains stack-based and heap-based buffer overflows. A long StyleTemplate element in a QUO, SUM or POR file overflows the stack, and a long Font->FaceName field overflows the heap. Both can crash the application and may allow arbitrary code execution.
Description
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName field (aka FaceName element), which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe CVSS 2.0 score is 10.0 with a network, unauthenticated vector and public exploit references, but the product is old and there is no KEV or ransomware evidence.
What it is
WinSig.exe in eSignal 10.6.2425 and earlier contains stack-based and heap-based buffer overflows. A long StyleTemplate element in a QUO, SUM or POR file overflows the stack, and a long Font->FaceName field overflows the heap. Both can crash the application and may allow arbitrary code execution.
Impact
An attacker can crash eSignal and potentially execute arbitrary code in the context of the WinSig.exe process. Successful code execution would give the attacker the privileges of the user running eSignal.
Attack surface
The flaw is reached remotely over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector. The attacker supplies a malicious QUO, SUM, POR or font file that WinSig.exe parses.
Exploitation
No CISA KEV listing and no ransomware association are recorded. EPSS is 0.55778 (99th percentile), and the references include an exploit advisory, indicating public exploit material exists.
What to do
- Upgrade eSignal to a version later than 10.6.2425, or apply the vendor fix referenced in the Secunia advisory.
- Block or restrict delivery of untrusted QUO, SUM, POR and font files to systems running eSignal.
- Run eSignal with least privilege so a successful overflow cannot gain elevated rights.
- Where the product is no longer supported, isolate it or retire it in favor of a maintained platform.
Detection
- Monitor for WinSig.exe crashes and abnormal process terminations, especially when opening QUO, SUM, POR or font files.
- Alert on WinSig.exe spawning child processes or making unexpected network connections after file parsing.
- Inspect inbound email and file transfer channels for QUO, SUM, POR and font files with oversized StyleTemplate or FaceName fields.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://aluigi.altervista.org/adv/esignal_1-adv.txt | Exploit |
| http://secunia.com/advisories/45966 | Vendor Advisory |
| http://aluigi.altervista.org/adv/esignal_1-adv.txt | Exploit |
| http://secunia.com/advisories/45966 | Vendor Advisory |
Track CVE-2011-3494 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3494), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.